Cardano-based DeFi platform Empowa has disclosed two connected incidents involving unauthorized transfers from three project-controlled wallets.

According to Empowa, the incidents involved its $ADA treasury wallet and two wallets holding undistributed EMP tokens. The project said the activity indicates that an unauthorized party gained control of the affected wallets’ private keys.

Empowa’s $ADA Treasury Wallet Compromised

The first incident involved Empowa’s Cardano treasury wallet, from which 143,710 $ADA was moved between November 2025 and June 2026.

The wallet also held 48,219 $NIGHT tokens claimed from Empowa’s Midnight airdrop allocation without the project’s knowledge. However, one-quarter of the $NIGHT allocation remains locked and requires another signature from the treasury wallet’s keys before it can be withdrawn.

Empowa said the unauthorized activity indicates that someone gained control of the treasury wallet’s keys before the first $ADA transfers. Although the wallet was initially considered locked, activity began on November 26, 2025.

Most of the transferred $ADA passed through an intermediary wallet. That wallet deposited 100,000 $ADA into the Liqwid lending protocol as collateral and borrowed USDCx against it. Subsequently, the wallet converted some of the funds into stablecoins and moved them off Cardano through transactions that appear consistent with cross-chain bridge redemptions.

Millions of EMP Tokens Also Moved

Notably, the second incident involved the $empowa. public and $empowa.ispo wallets, which held undistributed EMP tokens.

Between June and August 2026, 4.24 million EMP was transferred from the two wallets. Empowa said about 850,000 EMP moved during the first phase and was subsequently sold for $ADA on Minswap and VyFi.

The resulting $ADA was then converted into USDCx, with 4,810 USDCx sent to the same intermediary hub linked to the earlier treasury-wallet incident. Meanwhile, Empowa said part of the remaining EMP is still being sold on Minswap.

Empowa Rules Out Link to SecondFi Incident

Empowa emphasized that the unauthorized transfers were not connected to the SecondFi security incident disclosed in June 2026.

In that separate incident, hackers siphoned 16.1 million $ADA from 374 user wallets after exploiting a flaw in SecondFi’s wallet-generation software. Empowa pointed out that its treasury wallet showed unauthorized activity as early as November 2025, several months before the SecondFi incident became public.

Moreover, the affected Empowa wallets were enterprise addresses controlled by the project’s backend rather than consumer wallets generated through browser software.

According to Empowa, the activity instead points to deliberate and sustained control of the private keys. The same unauthorized key-holder registered the treasury wallet for Midnight’s Glacier Drop, claimed $NIGHT as the tokens unlocked, and later moved both $ADA and $NIGHT through other wallets.

Investigation Underway

In the meantime, Empowa said it has engaged blockchain investigators and continues to monitor the affected wallets.

The project also plans to pursue KYC information through legal channels if the stolen funds eventually reach centralized exchanges. The incident has nevertheless raised questions within the Cardano community, particularly about how the unauthorized activity continued for months without detection or a public report.

Some community members have speculated that the transfers could involve an insider. However, there is currently no confirmed evidence publicly establishing insider involvement, making that possibility speculation rather than a verified conclusion.